Skip to main content
EPSS 0.3%top 76%

Red Hat Security Advisory: RHOAI 2.25.7 - Red Hat OpenShift AI

0
High
Published: 06/10/2026 (06/10/2026, 04:27:13 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Release of RHOAI 2.25.7 provides these changes:

Affected software

Affected versions
=1.59=1.81=1.82Red HatRed Hat OpenShift AIRed Hat OpenShift AI 2.25amd64registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:befa28e03956fe8f135c850fc8ded8b210d5e49038812401372c5ee2baee73fd_amd64Red Hat JBoss AMQRed Hat AMQ Broker 7.13.5Red Hat Build of Apache CamelRed Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14Red Hat JBoss Enterprise Application PlatformRed Hat JBoss EAP 8.1 for RHEL 8srceap8-wildfly-openssl-el8-x86_64-0:2.3.0-1.Final.redhat.00001.1.el8eap.srcRed Hat Build of Apache Camel 4.14 for Quarkus 3.27Red Hat JBoss EAP 8.1 for RHEL 9eap8-wildfly-openssl-el9-x86_64-0:2.3.0-1.Final_redhat_00001.1.el9eap.srcRed Hat JBoss Enterprise Application Platform 8.1Red Hat OpenShift Dev SpacesRed Hat OpenShift Dev Spaces 3.28registry.redhat.io/devspaces/code-rhel9@sha256:b86a03ffcc1fc359116cc0ca231c64e5d612f047d41b5a2d44d1f3a9d880c14b_amd64Red Hat JBoss EAP 7.4 ELS for RHEL 7 Servereap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap.srcRed Hat JBoss Enterprise Application Platform 7.4.25Red Hat build of QuarkusRed Hat build of Quarkus 3.20.6.SP1Red Hat build of Quarkus 3.27.3.SP11.591.811.82Red Hat AMQ Broker 7.12.7Red Hat AMQ Broker 7.14.1

Weaknesses

CWE-327CWE-130CWE-770CWE-1289CWE-835CWE-502CWE-94CWE-22CWE-674CWE-474CWE-501CWE-829CWE-59CWE-915CWE-776CWE-347CWE-551CWE-306CWE-131CWE-409CWE-212CWE-79CWE-918CWE-90CWE-444CWE-226CWE-305CWE-1173CWE-367CWE-178CWE-208CWE-341CWE-338CWE-248CWE-772CWE-1333CWE-1389CWE-179CWE-940CWE-1188CWE-289CWE-917CWE-307CWE-385CWE-295CWE-117CWE-190CWE-93CWE-1286CWE-1287CWE-805CWE-346CWE-120CWE-1050CWE-303CWE-201CWE-168CWE-241CWE-606CWE-824CWE-839CWE-789CWE-184CWE-807CWE-911

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 19:51:28 UTC

Technical Analysis

CVE-2025-14813 is a cryptographic vulnerability in the BC-JAVA bcprov library's GOSTCTR implementation used by Red Hat products including OpenShift Dev Spaces. The GOSTCTR cipher reuses keystream after encrypting more than 255 blocks, violating fundamental confidentiality guarantees. An attacker who captures ciphertext encrypted beyond this limit can perform cryptanalysis to recover plaintext data. The vulnerability impacts confidentiality but not integrity or availability. Red Hat's advisory highlights the need to limit encryption payload size or transition to a secure authenticated encryption mode. No explicit patch or fix is currently provided; mitigation is procedural.

Potential Impact

The vulnerability allows attackers to break the confidentiality of data encrypted with the GOSTCTR implementation after more than 255 blocks are processed under the same key and IV. This can lead to full recovery of plaintext from ciphertext, compromising sensitive communications or stored data. There is no impact on data integrity or availability. No known exploits are reported in the wild. The severity is high due to the potential for complete data exposure.

Mitigation Recommendations

Currently, no official patch or fix is confirmed for this vulnerability. To mitigate the risk, users must strictly limit the amount of data encrypted under a single key and IV pair to a maximum of 255 blocks when using the GOSTCTR implementation. Alternatively, users should transition to a more secure, standardized, and authenticated encryption mode to avoid keystream reuse. Monitor Red Hat advisories for updates or patches addressing this issue.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:17668
Cve Count
23
Additional Cves
["CVE-2025-67030","CVE-2026-0636","CVE-2026-2332","CVE-2026-3505","CVE-2026-5588","CVE-2026-5795","CVE-2026-6857","CVE-2026-22731","CVE-2026-27446","CVE-2026-33453","CVE-2026-33454","CVE-2026-33870","CVE-2026-33871","CVE-2026-35554","CVE-2026-40022","CVE-2026-40453","CVE-2026-40858","CVE-2026-40860","CVE-2026-40972","CVE-2026-40973","CVE-2026-40975","CVE-2026-41635"]
State
PUBLISHED

Threat ID: 6a160958e29bf47b5061fbc1

Added to database: 05/26/2026, 20:58:00 UTC

Last enriched: 08/14/2026, 19:51:28 UTC

Last updated: 09/15/2026, 01:37:29 UTC

Views: 183

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:24977https://access.redhat.com/security/cve/CVE-2025-14813https://access.redhat.com/security/cve/CVE-2025-48956https://access.redhat.com/security/cve/CVE-2025-61726https://access.redhat.com/security/cve/CVE-2025-62718https://access.redhat.com/security/cve/CVE-2025-69227https://access.redhat.com/security/cve/CVE-2025-69228https://access.redhat.com/security/cve/CVE-2026-1462https://access.redhat.com/security/cve/CVE-2026-23490https://access.redhat.com/security/cve/CVE-2026-24747https://access.redhat.com/security/cve/CVE-2026-25048https://access.redhat.com/security/cve/CVE-2026-25960https://access.redhat.com/security/cve/CVE-2026-27489https://access.redhat.com/security/cve/CVE-2026-27893https://access.redhat.com/security/cve/CVE-2026-28500https://access.redhat.com/security/cve/CVE-2026-28684https://access.redhat.com/security/cve/CVE-2026-29063https://access.redhat.com/security/cve/CVE-2026-29074https://access.redhat.com/security/cve/CVE-2026-31958https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/errata/RHSA-2026:17668https://access.redhat.com/security/updates/classification/#critical244432024492902451409245245324524562455916245651924581872458634245863824586402458641246000324631722463173246317724631782463179https://access.redhat.com/errata/RHSA-2026:21772https://access.redhat.com/documentation/en-us/red_hat_openshift_dev_spaces/3.28/html/administration_guide/installing-devspaceshttps://access.redhat.com/security/cve/CVE-2025-68121https://access.redhat.com/security/cve/CVE-2026-0636https://access.redhat.com/security/cve/CVE-2026-1525https://access.redhat.com/security/cve/CVE-2026-1526https://access.redhat.com/security/cve/CVE-2026-1528https://access.redhat.com/security/cve/CVE-2026-1605https://access.redhat.com/security/cve/CVE-2026-2229https://access.redhat.com/security/cve/CVE-2026-2327https://access.redhat.com/security/cve/CVE-2026-26996https://access.redhat.com/security/cve/CVE-2026-27904https://access.redhat.com/security/cve/CVE-2026-30827https://access.redhat.com/security/cve/CVE-2026-31802https://access.redhat.com/security/cve/CVE-2026-32141https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-32305https://access.redhat.com/errata/RHSA-2026:18054https://access.redhat.com/security/updates/classification/#importanthttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.1https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.1/html/release_notes_for_red_hat_jboss_enterprise_application_platform_8.1/indexhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.1/html/red_hat_jboss_enterprise_application_platform_installation_methods/indexhttps://access.redhat.com/articles/7134190233762124412682442671244290824429222458635https://access.redhat.com/errata/RHSA-2026:18055https://access.redhat.com/errata/RHSA-2026:18059https://access.redhat.com/articles/7137769JBEAP-29032https://access.redhat.com/errata/RHSA-2026:11720https://access.redhat.com/products/quarkus/https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=redhat.quarkus&downloadType=distributions&version=3.20.6.SP1https://docs.redhat.com/en/documentation/red_hat_build_of_quarkus/3.20Canonical URLReference 79Reference 80Reference 81Reference 82Reference 83Reference 84Reference 85Reference 86https://access.redhat.com/security/updates/classification#importanthttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.13.5https://docs.redhat.com/en/documentation/red_hat_amq_broker/7.1324454492445451Canonical URLhttps://access.redhat.com/errata/RHSA-2026:53644https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index2467540247721724772202477224247722624772272477232247793024803252480601https://access.redhat.com/errata/RHSA-2026:53806https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=redhat.quarkus&downloadType=distributions&version=3.27.3.SP1https://docs.redhat.com/en/documentation/red_hat_build_of_quarkus/3.27Canonical URLhttps://access.redhat.com/security/cve/CVE-2026-3505https://access.redhat.com/security/cve/CVE-2026-5588https://access.redhat.com/security/cve/CVE-2026-35554https://access.redhat.com/security/cve/CVE-2026-398522457819Canonical URLCanonical URL2488062248808124883832488388248839124884002488413248842924884332488437248843924884422511026JBEAP-33515https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.12.7https://docs.redhat.com/en/documentation/red_hat_amq_broker/7.12Canonical URLReference 134Reference 135Reference 136Reference 137Reference 138Reference 139Reference 140Reference 141Reference 142Reference 143Reference 144https://access.redhat.com/errata/RHSA-2026:66488https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.14.1https://docs.redhat.com/en/documentation/red_hat_amq_broker/7.1424573212457323245732824638572467927247681024772192477231Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses